Skip to main content

Vendor/product archive

openclinic_ga_project / openclinic_ga CVEs

Beta · best-effort

37 CVEs tagged to openclinic_ga_project / openclinic_ga15 Critical, 17 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-40279

Published Mar 19, 2024

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40278

Published Mar 19, 2024

An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40280

Published Mar 19, 2024

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40277

Published Mar 19, 2024

An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40275

Published Mar 19, 2024

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37364

Published Oct 26, 2021

OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27246

Published May 11, 2021

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27245

Published May 11, 2021

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27244

Published May 11, 2021

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vul…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27243

Published May 11, 2021

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27242

Published May 11, 2021

An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27232

Published May 10, 2021

An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27231

Published May 10, 2021

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27230

Published May 10, 2021

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27229

Published May 10, 2021

A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27226

Published May 10, 2021

An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can mak…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27241

Published Apr 19, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthent…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27240

Published Apr 19, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauth…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27239

Published Apr 15, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27238

Published Apr 15, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated S…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27237

Published Apr 15, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27236

Published Apr 13, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27235

Published Apr 13, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27234

Published Apr 13, 2021

An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2